Following another cyber breach at the Federal Deposit Insurance Corporation, the House Science, Space and Technology Committee wants to know why it’s taking the agency so long to report the system attacks.
In an Oct. 21 letter to FDIC Chairman Martin Gruenberg, Committee Chairman Lamar Smith, R-Texas, and Oversight Subcommittee Chairman Barry Loudermilk, R-Ga., demanded to know why a breach discovered in August was not reported to the committee until Oct. 19 and had not classified it as a major breach.
“This recent incident, coupled with the agency’s slow-moving response, raises significant concerns about confusion at the FDIC on how to manage cybersecurity incidents, as well as a lack of leadership within the agency on cybersecurity issues,” the letter said.
The latest quarrel over FDIC’s cybersecurity centers on a breach of the agency’s “Search+” tool, a component of its Records and Information Management program.
The agency’s Computer Security Incident Response Team and later the Data Breach Management Team reportedly discovered on Aug. 9 that the tool had given all employees and contractors improper permissions to access more than 400 FDIC employees’ documents, including 27 Office of Inspector General field agents.
The committee letter said the files included “Suspicious Activity Reports, Grand Jury materials, ongoing OIG investigative materials and OIG deliberative materials,” but was not classified as a major breach because agency officials did not find “evidence of unauthorized access”.
FDIC officials did not report the breach to the committee — which has oversight authority of FDIC’s IT systems — until Oct. 19, vexing Smith and Loudermilk in light of a number of other breaches at the agency that were not immediately reported.
“FDIC’s decision to delay reporting this breach to Congress raises significant questions about why the agency would not be forthcoming when it initially learned about the incident,” the letter said.
Smith and Loudermilk go on to say that the committee only learned of the breach from an “independent receipt of information about the incident” and committee staff contacted the agency for more details.
“The FDIC’s lackluster response to cybersecurity incidents, evidenced by its response thus far to the ‘Search+’ breach, raises significant questions about the FDIC’s cybersecurity posture as a whole under your leadership, as well as your testimony before the committee during its July 14, 2016, hearing,” the letter said.
FDIC has been under fire from the committee for a number of cyber incidents that were not reported to Congress for months after they were discovered.
In April, the committee found that a former FDIC employee downloaded thousands of files of personally identifiable information — including American citizens’ Social Security numbers and loan and banking information — on to a portable hard drive before leaving for a job in the private sector.
Despite learning of the incident in October 2015, FDIC officials did not consider it a major breach and didn’t report it to Congress.
After an inspector general’s report disagreed with the agency’s assessment of the severity of the breach, FDIC reported it to Congress on Feb. 26, four months later.
The committee later learned of seven breaches at FDIC where outgoing employees left the agency with information affecting 160,000 individuals that were retroactively reported by chief information officer Larry Gross.
Gruenberg testified on July 14 that FDIC was incorporating policies to report cyber breaches in a more timely manner.
“Cybersecurity is a top priority for the FDIC,” an agency spokesperson said in an email to Federal Times. “The FDIC is committed to meeting our obligations for keeping Congress informed of cybersecurity incidents.”




